Community discussions

MikroTik App

Search found 13 matches

by Damago1
Mon Sep 30, 2024 2:11 am
Forum: General
Topic: Prevent L2TP server from creating dynamic interface
Replies: 1
Views: 240

Prevent L2TP server from creating dynamic interface

I have a problem. I have setup L2TP site-to-site tunnel. I am monitoring this tunnel with SNMP. The problem is that from time to time the connection drops, and immediately reconnects. When reconnecting it creates virtual interface with < and > brackets around name: /interface/l2tp-server/add name=&q...
by Damago1
Sun Sep 15, 2024 9:51 pm
Forum: General
Topic: Identity selection when Mikrotik working as initiator in ipsec
Replies: 1
Views: 532

Identity selection when Mikrotik working as initiator in ipsec

I have two questions reagrding identity /ip/ipsec/identity selection. 1. can the same identity be shared among several peer configurations? I read somewhere that it can, but from what I see the peer=xxx field is mandatory in identity. 2. How Mikrotik selects the identity when working as INITIATOR? M...
by Damago1
Sun Sep 15, 2024 6:22 pm
Forum: General
Topic: send-initial-contact v.s passive parameters of peer configuration in ipsec
Replies: 3
Views: 1096

Re: send-initial-contact v.s passive parameters of peer configuration in ipsec

The Mikrotik documentation often assumes the reader is familiar with the standards regarding the protocol (...) send-initial-contact literally means "send the INITIAL_CONTACT IKE notification", which suggests the recipient to drop any already existing connections authenticated using the s...
by Damago1
Sun Sep 15, 2024 5:45 pm
Forum: General
Topic: Mikrotik <-> Cisco IPsec IKEv2 VPN
Replies: 77
Views: 11388

Re: Mikrotik <-> Cisco IPsec IKEv2 VPN

It's actually a misconception I've suffered from myself for years. The send-initial-contact parameter has nothing to do with controlling whether the peer will initiate connections or not - this is what the passive parameter controls. INITIAL_CONTACT is an optional notification, asking the peer rece...
by Damago1
Sun Sep 15, 2024 5:04 pm
Forum: General
Topic: send-initial-contact v.s passive parameters of peer configuration in ipsec
Replies: 3
Views: 1096

send-initial-contact v.s passive parameters of peer configuration in ipsec

I have a question: What is the relation between send-initial-contact and passive parameters found in peer configuration under ipsec? What does it mean for mikrotik (how it affects behavior) if a mikrotik router is working as ipsec initiator if it has: a) send-initial-contact=no passive=no b) send-in...
by Damago1
Sun Sep 15, 2024 4:36 pm
Forum: General
Topic: Where can I find GOOD documetation of IPSEC in Mikrotik?
Replies: 6
Views: 903

Re: Where can I find GOOD documetation of IPSEC in Mikrotik?

The following is IMO one of the very best guides on creating your IPSec under MikroTik MikroTik IPSec ike2 VPN server: easy step-by-step guide by Nikita Tarikin Unfortunately this is NOT explaining anything else than MTU size (maximum trasfer unit). There is a 'ready' configuration given and there ...
by Damago1
Wed Sep 11, 2024 2:21 am
Forum: General
Topic: Where can I find GOOD documetation of IPSEC in Mikrotik?
Replies: 6
Views: 903

Re: Where can I find GOOD documetation of IPSEC in Mikrotik?

Huge thanks! I am one small step further. "Mikrotik looks for a corresponding static policy linked to that peer" Can you please clarify how can you assign "static policy" linked to peer? I do not see "policy" field in 'peer' and no such thing in 'idenity'. Do you mean, ...
by Damago1
Tue Sep 10, 2024 8:22 pm
Forum: General
Topic: Where can I find GOOD documetation of IPSEC in Mikrotik?
Replies: 6
Views: 903

Where can I find GOOD documetation of IPSEC in Mikrotik?

I am struggling to understand IPSEC in Mikrotik. There is a wiki article but it is very incomplete. Does anybody know where can I find information HOW EXACTLY mikrotik uses each part of configuration (profile, proposal, policy, policy group, peer, identity etc.). I understand how IPSEC works, but I ...
by Damago1
Sat Sep 07, 2024 10:28 pm
Forum: RouterOS beta
Topic: Feature Request - NAT64/DNS64 CGN
Replies: 36
Views: 27668

Re: Feature Request - NAT64/DNS64 CGN

+1` transition mechanisms will be more and more important. We are planning to migrate internal company structure to IPv6. And we will have to decide if to drop Mikrotik or to use some not elegant solution like extra server which is a pain becouse we manged to get rid of servers in many locations.
by Damago1
Sun Jun 16, 2024 10:36 pm
Forum: Useful user articles
Topic: Getting IPEv2/IPSec/PSK Mikrotik <-> Android 13+ VPNs working (and maybe other key sharing methods, too)
Replies: 3
Views: 17567

Re: Getting IPEv2/IPSec/PSK Mikrotik <-> Android 13+ VPNs working (and maybe other key sharing methods, too)

Just in case (google points here) below is a working configuration of ipsec ikev2 / psk vpn: notes: 1.this configuration is NOT touching the "default" profile, "default" identity etc. So it should work in parallel with other VPN types, for instance in paralell with L2TP/ipsec VPN...
by Damago1
Sun Jun 16, 2024 10:34 pm
Forum: General
Topic: IkeV2 VPN server setup for Android 13
Replies: 5
Views: 8073

Re: IkeV2 VPN server setup for Android 13

Here is a working configuration of ipsec ikev2 / psk vpn: notes: 1.this configuration is NOT touching the "default" profile, "default" identity etc. So it should work in parallel with other VPN types, for instance in paralell with L2TP/ipsec VPN which is creating dynamic identity...
by Damago1
Fri Jan 12, 2024 10:57 am
Forum: Scripting
Topic: add succesfully connected rdp to whitelist
Replies: 6
Views: 1900

Re: add succesfully connected rdp to whitelist

I was trying to do something mikrotik only. Without adding complexity and another scripts to servers which would add another thing to maintain etc. My latest attempt is to try to guess by amount of traffic: /ip firewall filter add action=add-src-to-address-list address-list=rdp_whitelist \ address-l...
by Damago1
Wed Jan 10, 2024 9:31 pm
Forum: Scripting
Topic: add succesfully connected rdp to whitelist
Replies: 6
Views: 1900

add succesfully connected rdp to whitelist

I would like to add succesfully connected rdp connections to whitelist. And I have no clue how to detect if the connection is succesfully established or it is just another brute force attempt. I was trying something like": chain=forward action=add-src-to-address-list connection-state=establishe...